CVE-2026-107639 — ILIAS before 9.24, 10.x before 10.12 and 11.x before 11.5 contains an argument injection vulnerability in assImagemapQuestionGUI that allows questi…
Description
ILIAS before 9.24, 10.x before 10.12 and 11.x before 11.5 contains an argument injection vulnerability in assImagemapQuestionGUI that allows question authors to inject ImageMagick convert options via uploaded image filenames. Attackers can embed tab-separated options, which escapeshellcmd() does not neutralise, to write a PHP file under the web root and achieve remote code execution.
CVSS v4.0 base metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XHigh severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Network
Attack Vector
AC
Low
Attack Complexity
AT
None
Attack Requirements
PR
Low
Privileges Required
UI
None
User Interaction
VC
High
Confidentiality (Vulnerable System)
VI
High
Integrity (Vulnerable System)
VA
High
Availability (Vulnerable System)
SC
None
Confidentiality (Subsequent System)
SI
None
Integrity (Subsequent System)
SA
None
Availability (Subsequent System)
References
- advisory[email protected]https://docu.ilias.de/go/blog/15821/950
- advisory[email protected]https://docu.ilias.de/go/blog/15821/951
- advisory[email protected]https://docu.ilias.de/go/blog/15821/952
- advisory[email protected]https://github.com/ILIAS-eLearning/ILIAS
- advisory[email protected]https://github.com/ILIAS-eLearning/ILIAS/blob/v10.11/components/ILIAS/TestQuestionPool/classes/class.assImagemapQuestion.php#L290-L306
- advisory[email protected]https://github.com/ILIAS-eLearning/ILIAS/blob/v10.11/components/ILIAS/TestQuestionPool/classes/class.assImagemapQuestionGUI.php#L130
- advisory[email protected]https://github.com/ILIAS-eLearning/ILIAS/blob/v10.11/components/ILIAS/TestQuestionPool/classes/class.ilImagemapPreview.php#L208-L238
- advisory[email protected]https://github.com/ILIAS-eLearning/ILIAS/commit/ad1423c365a7ffd25bac711d995c643ce2af65c6
- advisory[email protected]https://www.vulncheck.com/advisories/ilias-before-9.24-10.12-and-11.5-argument-injection-via-image-map-question-upload-filename
Related threats
same CWE or vendorCVE-2026-19482 — IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote authenticated attacker to …
CVE-2026-19482 · 2h ago
CVE-2026-18740 — IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote authenticated attacker to …
CVE-2026-18740 · 2h ago
CVE-2026-11939 — IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 may be vulnerable to audit log forgery.
CVE-2026-11939 · 2h ago
CVE-2026-107510 — An authenticated high privilege user can inject arguments in troubleshooting commands resulting in privilege escalation.
CVE-2026-107510 · 13h ago
CVE-2026-93699 — Argument injection in WP Toolkit for cPanel allows local users to execute arbitrary code as other accounts on the same server.
CVE-2026-93699 · 15h ago
CVE-2026-87687 — An authorization and input validation vulnerability exists in Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1.
CVE-2026-87687 · 19h ago